« Laptop encryption | Main | HSBC lose a server »

Insider Threats: the biggest Information Security risk

It's a fact that most crimes are committed by people known to their victims. Similarly, businesses are most at risk from former and current employees. Most commonly when thinking about information security we consider how to prevent intrusion into our business from the outside. The facts and statistics tell a different story. 62% of large businesses in the UK (source: DTI/PWC Insider Threat Report 2006) have dealt with a security incident instigated by a current or former employee.

I've been writing up some of my research into insider threats in the form of a paper describing the risks posed to a fictional multinational company, Acme Widgets plc.

You can download the paper for free here. If you'd like to leave me feedback or would like more information about insider threats, write to the email address within the digital signature at the end of the document.

If you'd like to make a donation in return for downloading the paper, please give to Children in Need.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/27086

Comments (2)

Anton Chuvakin:

How can a THREAT be the biggest RISK?

Shouldn't one of the 'threats' be the biggest one?

Mixing up basic terminology sure gives security a bad name (and supports the idea that "security is some kind of black art") in the eyes of many IT and non-IT people ....

Stuart King:

Thanks Anton - yes, I know. The title could probably have been expressed slightly better. It's supposed to represent my view that the greatest risks evolve from insider threats...make sense?

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on May 10, 2008 4:00 PM.

The previous post in this blog was Laptop encryption.

The next post in this blog is HSBC lose a server.

Many more can be found on the main index page or by looking through the archives.